Browse Rules

Search and filter across all detection sources

182 rules

sentinel low kql

API - Anomaly Detection

'42Crunch API protection anomaly detection'

sagan medium other

[CISCO-PRIME] MFP anomaly detected

[CISCO-PRIME] MFP anomaly detected

sagan informational other

[FORTINET] UTM Anomaly Event Detected

[FORTINET] UTM Anomaly Event Detected

sagan informational other

[FORTINET] UTM Anomaly Event Detected

[FORTINET] UTM Anomaly Event Detected

sagan low other

[MCAS] ALERT_DISCOVERY_ANOMALY_DETECTION

[MCAS] ALERT_DISCOVERY_ANOMALY_DETECTION

sagan medium other

[NETSKOPE] Anomaly Alert Detected (High)

[NETSKOPE] Anomaly Alert Detected (High)

sagan medium other

[NETSKOPE] Anomaly Alert Detected (Low)

[NETSKOPE] Anomaly Alert Detected (Low)

sagan medium other

[NETSKOPE] Anomaly Alert Detected (Medium)

[NETSKOPE] Anomaly Alert Detected (Medium)

sagan unknown other

[FORTINET] Attack Detected by ICMP Anomaly

[FORTINET] Attack Detected by ICMP Anomaly

sagan unknown other

[FORTINET] Attack Detected by Other Anomaly

[FORTINET] Attack Detected by Other Anomaly

sagan unknown other

[FORTINET] Attack Detected by Other Anomaly

[FORTINET] Attack Detected by Other Anomaly

sagan unknown other

[FORTINET] Attack Detected by Other Anomaly

[FORTINET] Attack Detected by Other Anomaly

panther low python

Slack Anomaly Detected

Passthrough for anomalies detected by Slack

sagan unknown other

[FORTINET] Attack Detected by UDP/TCP Anomaly

[FORTINET] Attack Detected by UDP/TCP Anomaly

signature-base unknown yara

SUSP_Sysinternals_Desktops_Anomaly_Feb25 [yara]

Detects anomalies in Sysinternals Desktops binaries

wazuh low xml

Host-based anomaly detection event (rootcheck).

Host-based anomaly detection event (rootcheck).

sentinel medium kql

Unusual Anomaly

'Anomaly Rules generate events in the Anomalies table. This scheduled rule tries to detect Anomalies that are not usual, they could be a type of Anomaly that has recently been activated, or an infrequent type. The detected Anomaly should be reviewed, if it is relevant enough, eventually a separate scheduled Analytics Rule could be created specifically for that Anomaly Type, so an alert and/or incident is generated everytime that type of Anomaly happens.'

sentinel medium kql

Vaikora - Behavioral anomaly detected

Identifies AI agent behavioral anomalies flagged by Vaikora with an anomaly score of 0.7 or above, indicating significant deviation from the agent's established behavioral baseline.

signature-base unknown yara

PowerShell_Case_Anomaly [yara]

Detects obfuscated PowerShell hacktools

signature-base unknown yara

WScriptShell_Case_Anomaly [yara]

Detects obfuscated wscript.shell commands

signature-base unknown yara

SUSP_Microsoft_Copyright_String_Anomaly_2 [yara]

Detects Floxif Malware

signature-base unknown yara

SUSP_GIF_Anomalies [yara]

Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type

anvilogic high spl

Auth0: User block released from anomaly detection [splunk-auth0]

Monitoring the release of a blocked user from anomaly detection being lifted. This could signal a legitimate user regaining access or a potential attacker bypassing security controls to regain entry. This rule will monitor events for ""ublkdu", OR "User block setup by anomaly detection has been released" with user blocks being released by anomaly detection, helping to identify potential unauthorized access or suspicious authentication activity.

hayabusa medium sigma

Potential Regsvr32 Commandline Flag Anomaly

Detects a potential command line flag anomaly related to "regsvr32" in which the "/i" flag is used without the "/n" which should be uncommon.

sigma medium sigma

Potential Regsvr32 Commandline Flag Anomaly

Detects a potential command line flag anomaly related to "regsvr32" in which the "/i" flag is used without the "/n" which should be uncommon.